CVE-2026-76940
Deferred Deferred - Pending Action

Authentication Bypass in Ebyte Device via Repeated Attempts

Vulnerability report for CVE-2026-76940, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-28

Last updated on: 2026-08-31

Assigner: ICS-CERT

Description

The affected Ebyte device does not restrict repeated authentication attempts through rate limiting or account lockout mechanisms. This could allow an attacker to perform automated authentication attacks against deployments that rely on password based authentication.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-28
Last Modified
2026-08-31
Generated
2026-09-17
AI Q&A
2026-08-28
EPSS Evaluated
2026-09-15
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
ebyte csafpid-0001 *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-307 The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The vulnerability involves an Ebyte device lacking rate limiting or account lockout mechanisms during authentication attempts. This allows attackers to repeatedly attempt authentication without restrictions, potentially enabling brute force or automated attacks against password-based systems.

Detection Guidance

This vulnerability involves lack of rate limiting or account lockout in Ebyte devices. To detect it, monitor authentication logs for repeated failed login attempts from the same source. Use network traffic analysis tools like tcpdump or Wireshark to capture authentication packets and identify brute force patterns. Check device logs for unusual authentication activity during off-hours.

Impact Analysis

An attacker could exploit this to gain unauthorized access to the device or system by guessing passwords through automated attempts. This may lead to data breaches, unauthorized control of the device, or disruption of services relying on the device.

Compliance Impact

This vulnerability could violate compliance requirements that mandate strong authentication controls, such as GDPR's data protection principles or HIPAA's security rules. Failure to implement rate limiting may result in non-compliance, potential fines, or legal liabilities.

Mitigation Strategies

Enable rate limiting or account lockout mechanisms on the Ebyte device to prevent repeated authentication attempts. Monitor authentication logs for unusual activity and consider implementing multi-factor authentication if supported.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-76940. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart